DOCS
Authentication
Every request is authenticated with a single secret API key.
tickstream uses a single secret API key per account. Pass it as a Bearer token on
REST requests, or as a key query parameter when opening a WebSocket.
Your key
Find and manage your key in the dashboard. Keys are prefixed
sk_live_ and grant full access to your plan — keep them server-side and never commit
them to source control.
REST requests
Authorization: Bearer sk_live_…curl https://api.tick-stream.xyz/v1/quote?symbol=ES \
-H "Authorization: Bearer sk_live_…"
A client that can send a URL but not a header — Sierra Chart's ACSIL is the usual one — may pass the
key as ?key=sk_live_… instead. The header wins when both are present. Prefer the header
everywhere else: a key in a URL ends up in proxy and browser logs.
WebSocket connections
wss://stream.tick-stream.xyz/v1?key=sk_live_…&symbols=ES The WebSocket reads the key from the key query parameter only; an Authorization header on the upgrade request is not read. Keep URLs with the key out of logs you share.
Rotating a key
If a key leaks, rotate it from the dashboard with one click. The old key stops working immediately, so update your services first. tickstream supports one active key per account today — need multiple scoped keys? Tell us.
Auth errors
| Status | Meaning |
|---|---|
401 | Missing or invalid API key. |
403 | Key valid, but your plan doesn't include this feed. The code names the reason: options_plan_required, request_type_not_in_plan, gex_plan_required, data_plan_required, plan_required, or account_suspended. |
See Limits & errors for the full error model.